TheTechGuide Forum
General Category => Software => Topic started by: bakuryu on July 21, 2004, 11:52:57 AM
-
Hello i dont know how this happened. But for somereason my home page has now become this SEARCH ADWARE thing. i change it to google.com but it keeps going to The same thing. I ran HIJACK this to get nothing of adware sort. Can u please help me. I did ADAWARE deleted some stuff but still this thing is here as my homepage. :S i looked in my system32 folder, no where in it is a file named ssearch.biz
/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> this is making me mad. I have run CWSHREDDER also.
-
I have had the same problem. This was the worst Hajacking I have ever had I must of tried ever program out there.
Got www.adwareaway.com download that when you install follow the instuctions reboot strat your internet up BINGO back to normal.
Good Look
CH
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
-
I think all of u have an xxx experiences !!!... Ha Ha Ha
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
-
get Adware Away from AdwareAway.com
-
I have had the same problem :
/ohmy.gif\' class=\'bbc_emoticon\' alt=\':o\' />
I Know Is A Sex Trekar
/blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' />
But I Want To Removd This Soft
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
-
I have had the same problem :
/ohmy.gif\' class=\'bbc_emoticon\' alt=\':o\' />
I Know Is A Sex Trekar
/blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' />
But I Want To Removd This Soft
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
-
Hello, i downloaded this adwareaway software ran it. DIdnt find much, i clicked on fix fast and rebooted. THe Page is still there :S
-
Ok i just noticed the other options below such as MALWARE, ADWARE, SPYWARE, and TROjans/Worms i did those scanned and found a couple removed them, rebooted and the yet the pAGE is STILL THERE. Do any of u know what the file name is.
-
[quote name=\'bakuryu\' date=\'Jul 21 2004, 10:52 AM\']Hello i dont know how this happened. But for somereason my home page has now become this SEARCH ADWARE thing. i change it to google.com but it keeps going to The same thing. I ran HIJACK this to get nothing of adware sort. Can u please help me. I did ADAWARE deleted some stuff but still this thing is here as my homepage. :S i looked in my system32 folder, no where in it is a file named ssearch.biz
/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> this is making me mad. I have run CWSHREDDER also.[/quote]
hi i have the same i face alote like i solved be deleted manule on system32 like service on system32 folder
-
file is regcmd32 i think . use hijack this or regedit to remove from startup also go to properties on your IE desktop icon and check 4 dodgy paths . hope this helps
-
get spybot search and distroy from
http://www.spybot.info/en/index.html (http://\"http://www.spybot.info/en/index.html\")
that should let you get rid of your spyware
-
SpyBot does not remove this hijacker.
-
He is right, S&D nore the other remove this one yet, it is new.
Only one claims to be able to, almost like they hare the cure before the desease. Could the current fix some mention for this threat be from the actual author of the hijack?? Are you sure your not installing a backdoor in the process...
Some people just install anything, and then trust anyone to remove it...
-
I too had this rude little intrusion and it was detected as the cool web search trojan cws.smartsearch.2
it kept redirecting my browser to "ssearch.biz/?wmid=1010" searchpage
I tried Trend pc cillan, Norton, cws shredder ,spybot s&d, adaware6.0 ,trojan hunter - all to no avail
... it kept me busy and frustrated for over a week untill I found T-Zero's remedy and now it is finally gone ..here is the link to T-Zero's thread
http://forums.net-integration.net/index.ph...t=0entry94408 (http://\"http://forums.net-integration.net/index.php?showtopic=20383&st=0&#entry94408\")
Good luck you guys ....be careful with "hijack this"
Thankyou T-Zero
-
I too suspect that the adwareaway folks may have manufactured this malware. They're newbies to the industry (Posted to download.com on 7/15) yet have an exclusive fix for a brand new treat? Too good to be true IMHo...
-
Are you still having the problem? If so reply to this post or make a new one and I will walk you through the steps.
-
[quote name=\'bakuryu\' date=\'Jul 21 2004, 10:52 AM\']Hello i dont know how this happened. But for somereason my home page has now become this SEARCH ADWARE thing. i change it to google.com but it keeps going to The same thing. I ran HIJACK this to get nothing of adware sort. Can u please help me. I did ADAWARE deleted some stuff but still this thing is here as my homepage. :S i looked in my system32 folder, no where in it is a file named ssearch.biz
/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> this is making me mad. I have run CWSHREDDER also.[/quote]
you can find where it is hiding by searching in[for files and folders] make sure you click on search hidden files and folders
try both full web site address and ?wmid1010 you should get a listing of hidden folders it is in open them then delete
hpoe this will solve your probs
-
/cool.gif\' class=\'bbc_emoticon\' alt=\'B)\' /> try Webroot-spy sweeper and turn on all the blocks and shields., just read and do what they say ....it works ....and throw all the others away.....after months of putting up with this little pest ,finally got it gone.......
/laugh.gif\' class=\'bbc_emoticon\' alt=\':lol:\' />
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' /> also for some reason the new browser that looks like internet exployer ....used to be ie4u. ... now Maxthon works fine. --I used ie4u for months with no problems...no pests at all , went back to internet exp. and bingo...back again ......ok ok ...now you will say i visit the xxxx sites.
/blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' /> ...sure everyone has to look ,,,right??? but anyway the only way to keep everything clean is just dont turn on the net..... back to the stone age!!!
food for thought-:
for some reason i noticed that when the little pest loaded it had an add for a spyware remover close to the top ....could there be some conspiracy.....remember the people who write these programs ...some used to be hackers.etc.......you figure it out...i give up ......just keep spending more money to keep ahead. ---PT Barnum must be alive!!!!---
/ph34r.gif\' class=\'bbc_emoticon\' alt=\':ph34r:\' />
-
Ok here is what this thing is:
it's full name is :CWS_pnpsvc-nqtwz]'c.dll
it is a CWS About Blank Hijack that lives in XP here :
C:\Windows\System32 NQTWZ.dll
Hijack This, AdAway, Spybot 1.3, Ad Aware, Spysweeper free edition, StartDreck, etc will not remove it.
I spent 12 Hours getting to the bottom if this for one of my clients.
Microsoft was no help at all event though it's there Browser I would have had to wait 5 days for level 2 support.
Webroot Technicians gave me a free full Version 3.2 yes you have to buy it version to test it our after I explained to them what a fning problem this thing was.
You can try deleteing the .dll in safemode manually I dont know if it will work as the thing is memory resident but it might. Otherwise break down and buy the full verion of Spysweeper or reformat.
If you want to send me a few bucks for my trouble Tom Fallon 26 Perch Pond Chatham Ma 02633 Thanks in advance. If not np but this is as of 9 1 04 the only fix that works and it found it in like 4 minutes.
Email me if you find this helpful
Tom
-
[quote name=\'happy for once\' date=\'Aug 21 2004, 07:11 PM\']
/cool.gif\' class=\'bbc_emoticon\' alt=\'B)\' /> try Webroot-spy sweeper and turn on all the blocks and shields., just read and do what they say ....it works ....and throw all the others away.....after months of putting up with this little pest ,finally got it gone.......
/laugh.gif\' class=\'bbc_emoticon\' alt=\':lol:\' /> :[/quote]
Hmm...I actually purchased Webroot this week and upgraded the app and all signature files. But they are not able to clean this one up. In fact if you go to there website you'll not they are saying it will be a minimum of two weeks before they have a viable fix. So far that was $30 flushed down the toilet I would stay away from WebRoot.
-
http://ssearch.biz/?wmid=1010 (http://\"http://ssearch.biz/?wmid=1010\") hijacker
I spent ages trying to remove this hijacker from a PC. As others said the usual programs don't find it. It hijacks 'My Computer' as well as IE.
In the end it was quite simple to remove. WinPatrol identified a running process sdspebpo.exe. A web search on this file found nothing (hence it seemed suspicious) so I killed that task and suddenly IE and My Computer came up properly. Ran msconfig and unticked this prog from the startup (it was showing as a 'DNS Cache') and rebooted - It didn't come back - SUCCESS! (well hopefully - haven't connected that PC to the internet yet).
-
Yes i finally got rid of ssearch.biz !!!!!!
They only thing you need is (free version) adware away
And follow the steps by them on there site
http://adwareaway.com/ssearchbiz.htm (http://\"http://adwareaway.com/ssearchbiz.htm\")
Fist i got an error but with help from there support i am free of ssearch.biz
-
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
Dear All,
I have just removed sucessfully the tough ssearch.biz with only one time refer this page and use also only one time of the excellent Adaware Away.
Thanks a lot to this forum.
vucanxuan1965Email Removed
-
Download this tool http://p-nand-q.com/download/pserv_cpl/pserv-2.3.exe (http://\"http://p-nand-q.com/download/pserv_cpl/pserv-2.3.exe\") and install it
Set your Explorer up using the info in this link so that hidden and System files are visible
Also Uncheck the "Hide extensions for known file types" box
Reboot to SAFE mode
How to start the computer in Safe mode
Rename the C:\WINNT\Regedit.exe file to oldreg.bin
It appears to be infected and you will have to replace it from CD
Start the program we installed (use Start > All Programs > pserv.cpl > Services and Devices)
(my spanish is awful)
When it opens find the Plug and Play svc service
Right click and choose Kill - then set it disabled (or even delete it)
Reboot and check -- did it come back ?
Fix the entries using HijackThis
extract a new regedit.exe file
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
-
hi all
This is the answer to all of you that were unable to remove ssearch.biz:
http://www.members.shaw.ca/AdwareAway/AdwareAway.exe (http://\"http://www.members.shaw.ca/AdwareAway/AdwareAway.exe\")
it does work , did it 5 mins ago 100%
you only need to select the hijaker to be removed and thats it
good luck to all of you
its good to try somthing that you know that it works 100%
-
Finally!!!!!!!!!!!!!!!!!!!!!!!!!!!!! i was freakin ' out due to this goddamned ssearchbiz......
adwareaway solved all my problems 1 min. ago!!!!!! thanks to everybody!!!!!!
i apologize for my bad english....but i'm from Milano Italia.....thanks thanks thanks
-
Dear all,
I recently ran into this virus as well. While I have tried to chip away at this for quite a while (2 months), I finally found it. This is a virus created by 180solutions. It is found in a System32 Folder--download the Xoftspy software and do a search ONLY on the System32 folder. It will come up with a folder that is named something like FLEOK. Find this folder and delete it. No need to buy anything.
http://ssearch.biz/?wmid=1010 (http://\"http://ssearch.biz/?wmid=1010\")
Hope this works for all of you....
-
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' /> http://ssearch.biz/?wmid=1010 (http://\"http://ssearch.biz/?wmid=1010\")
To delete this [censored] .
Delete all the folder in Content.IE5 in the Temporary Internet Files ,included the dustbin !!!!!!
-
New conga line!!!
1.http://www.mp3players4free.com/default.aspx?r=4070
2.http://www.mp3players4free.com/default.aspx?r=14984
3.????????
4.????????
5.????????
To be part of this conga line, e-mail me at habjabEmail Removed with the following info:
1. referral link
2. offer completed
3. e-mail you used to sign up for the FREE mp3 player
PS: Do not e-mail me if you don't use these referral links to sign up! Also, YOU MUST SIGN UP UNDER THE FIRST LINK OR YOU WILL NOT BE ADDED!
Thanks for your time and good luck!